<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Insecure Or Cleartext Authentication Detected Rule in Security</title>
    <link>https://community.splunk.com/t5/Security/Insecure-Or-Cleartext-Authentication-Detected-Rule/m-p/587874#M15964</link>
    <description>&lt;P&gt;Logon Type 8 is generated when something was logged onto through the network using a cleartext password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That last sentence from the Microsoft Documentation&amp;nbsp; is a little confusing for me too. I had to read it a few times to understand what it was referencing.&lt;/P&gt;&lt;P&gt;During Network Logins, the Server that is being logged into has previously cashed those credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;During authentication, hashes are created and sent to the Server are used to compare to what the computer has cached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was done without utilizing SSL/TLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 15:23:38 GMT</pubDate>
    <dc:creator>Stefanie</dc:creator>
    <dc:date>2022-03-07T15:23:38Z</dc:date>
    <item>
      <title>Insecure Or Cleartext Authentication Detected Rule</title>
      <link>https://community.splunk.com/t5/Security/Insecure-Or-Cleartext-Authentication-Detected-Rule/m-p/587835#M15963</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;Rule "Insecure Or Cleartext Authentication Detected" detects says when Logon type "8" is detected in windows logs.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As per &lt;STRONG&gt;Splunk&lt;/STRONG&gt; :&lt;BR /&gt;Detects authentication requests that transmit the password over the network as cleartext (unencrypted)&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunksecurityessentials.com/content-detail/insecure_or_cleartext_authentication_detected/" target="_blank" rel="noopener"&gt;https://docs.splunksecurityessentials.com/content-detail/insecure_or_cleartext_authentication_detected/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;As Per &lt;STRONG&gt;Windows&lt;/STRONG&gt;:&amp;nbsp;&lt;BR /&gt;The credentials do not traverse the network in plaintext (also called cleartext).&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Could you please let us know why this difference in description, This is creating some challenges in understanding the logs.&lt;BR /&gt;&lt;BR /&gt;Can someone help on this.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 11:25:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Insecure-Or-Cleartext-Authentication-Detected-Rule/m-p/587835#M15963</guid>
      <dc:creator>maalyu1612</dc:creator>
      <dc:date>2022-03-07T11:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Insecure Or Cleartext Authentication Detected Rule</title>
      <link>https://community.splunk.com/t5/Security/Insecure-Or-Cleartext-Authentication-Detected-Rule/m-p/587874#M15964</link>
      <description>&lt;P&gt;Logon Type 8 is generated when something was logged onto through the network using a cleartext password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That last sentence from the Microsoft Documentation&amp;nbsp; is a little confusing for me too. I had to read it a few times to understand what it was referencing.&lt;/P&gt;&lt;P&gt;During Network Logins, the Server that is being logged into has previously cashed those credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;During authentication, hashes are created and sent to the Server are used to compare to what the computer has cached.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This was done without utilizing SSL/TLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 15:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Insecure-Or-Cleartext-Authentication-Detected-Rule/m-p/587874#M15964</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-07T15:23:38Z</dc:date>
    </item>
  </channel>
</rss>

